The New York DFS Cybersecurity Regulation, 23 NYCRR Part 500, is a rule from the New York State Department of Financial Services (DFS) that requires the financial services companies it licenses or regulates to maintain a risk-based cybersecurity program, meet specific control requirements and certify compliance each year. First issued in 2017 and significantly amended in 2023, it covers organizations such as insurers, insurance agencies, banks, lenders and money transmitters operating under New York authorizations. Its requirements reach into IT providers through third-party service provider rules. This entry is an overview for buyers, not legal advice; confirm current requirements with DFS guidance or counsel.
At a glance
- Applies to entities operating under a license, registration, charter or similar authorization under New York’s Banking, Insurance or Financial Services laws.
- Requires a cybersecurity program and policies based on a risk assessment and, for most covered entities, a CISO and controls such as MFA, asset inventory, encryption, logging, training and testing.
- Reportable incidents generally go to DFS within 72 hours of determination; extortion payments have separate notice rules.
- Each covered entity files an annual certification of material compliance or an acknowledgment of noncompliance by April 15.
- Larger “Class A” companies face added requirements, while smaller entities may qualify for a limited exemption.
What problem it solves
Financial services firms hold sensitive personal and financial data and are frequent targets for ransomware, fraud and account takeover. Before Part 500, cybersecurity expectations for many state-licensed firms, especially smaller insurers and agencies, were general and uneven. DFS set specific minimum requirements and made senior leaders personally sign off on compliance.
The regulation also addresses a weak point: vendors. Many incidents start at a service provider, so Part 500 requires covered entities to set minimum security practices for their providers and check them, which brings third-party risk management (TPRM) into scope.
How it works
Program and governance. Each covered entity maintains a cybersecurity program and written policies approved by senior leadership, informed by a risk assessment that is reviewed periodically. Unless an exemption removes the requirement, a CISO, who can be employed by an affiliate or a third party such as a virtual CISO provider, reports to the board or senior governing body.
Technical controls. Requirements include multi-factor authentication (MFA) for individuals accessing information systems (with a narrower scope for entities under the limited exemption and room for CISO-approved compensating controls), an asset inventory, access privilege limits and reviews, encryption of nonpublic information, audit trails, secure application development practices, monitoring, training and data disposal.
Testing. Covered entities outside the limited exemption conduct penetration testing at least annually by a qualified internal or external party, plus vulnerability scanning at a frequency set by their risk assessment and after material changes.
Third-party service providers. Written policies identify and assess providers, set minimum security practices, require due diligence and periodic reassessment, and address MFA, encryption, incident notice and representations in contracts or due diligence.
Incident response and reporting. Entities keep incident response and business continuity plans, notify DFS of reportable incidents generally within 72 hours of determining they occurred, report extortion payments within 24 hours with a written explanation within 30 days, and file the annual compliance notice.
Covered entity categories
Part 500’s main structure is by entity size and type. The thresholds below reflect the current amended regulation; confirm with DFS or counsel before relying on them.
| Category | Who it applies to | What’s required | Typical evidence |
|---|---|---|---|
| Class A company | Covered entities with at least $20 million in gross annual revenue in each of the last two fiscal years from all of the covered entity’s business operations plus the New York business operations of its affiliates, and either more than 2,000 employees averaged over the last two fiscal years or more than $1 billion in gross annual revenue in each of the last two fiscal years, in both cases counting the covered entity and its affiliates wherever located (affiliates count only if they share information systems, cybersecurity resources or part of a cybersecurity program with the covered entity) | Full requirements plus added duties, including independent audits of the cybersecurity program, endpoint detection and response, and centralized logging and alerting (or CISO-approved equivalents) | Independent audit reports, annual certification, risk assessments, test results |
| Standard covered entity | Covered entities that are not Class A and don’t qualify for an exemption | Full program, CISO, controls, testing, notices and annual compliance filing | Policies, risk assessment, penetration test and scan results, MFA and asset inventory evidence, annual certification |
| Limited exemption | Covered entities meeting any one of: fewer than 20 employees and independent contractors of the covered entity and its affiliates; less than $7.5 million in gross annual revenue in each of the last three fiscal years from all of the covered entity’s business operations plus the New York business operations of its affiliates; or less than $15 million in year-end total assets, calculated under GAAP and including all affiliates’ assets | A reduced set of requirements: still a program, policies, risk assessment, access controls, MFA (for remote access and privileged accounts), notices and the annual filing, among others; no CISO requirement; notice of exemption filed with DFS | Notice of exemption, policies, risk assessment, annual filing |
| Other exemptions | For example, entities fully covered by an affiliated covered entity’s program, or entities that don’t use information systems or hold nonpublic information | Varies by exemption; a notice of exemption is generally required | Notice of exemption, documentation of the basis |
When it matters for buyers
- When you hold a New York financial services authorization. Your cloud, MSP, UCaaS and contact center providers need to fit your Part 500 program.
- When signing or renewing IT providers. Expect to document due diligence and contract terms on access, MFA, encryption and incident notice.
- Before the April 15 filing. Senior leaders sign, so they need evidence, not assumptions.
- When an incident hits a provider. Your 72-hour clock can apply to incidents at a third-party service provider.
Our governance, risk and compliance overview covers program-building, vCISO and assessment help.
Questions to ask vendors
- How quickly will you notify us of a cybersecurity event affecting our systems or nonpublic information, so we can meet our 72-hour obligation?
- Do you enforce MFA for everyone who can access our data, including your own staff?
- Is our nonpublic information encrypted in transit and at rest, and who controls the keys?
- What independent security reports can you share, and are they scoped to this service?
- Will you accept contract terms covering security representations, incident notice and cooperation with DFS inquiries?
- Can you supply evidence that supports our annual certification?
How it differs from GLBA
The Gramm-Leach-Bliley Act (GLBA) is a US federal law that sets privacy and safeguards duties for financial institutions nationwide, enforced by different federal and state regulators. Part 500 is a New York regulation that applies to DFS-licensed entities and is more prescriptive in places, with annual executive certification and specific notice deadlines. Many New York-licensed firms are subject to both. Public companies may also face the SEC cybersecurity disclosure rules, and many firms use the NIST Cybersecurity Framework (NIST CSF) to organize a program that meets all of them.
